Legal

Privacy Policy

Effective date: August 5, 2026 · Last revised: August 5, 2026 · Version 2026.08.05

This Privacy Policy (the “Policy”) sets forth the practices of the operator of the Tavi product and related websites, messaging endpoints, application programming interfaces, and administrative tooling (collectively, “Tavi,” “we,” “us,” or “our”) with respect to personal data and other information processed in connection with your access to or use of Tavi’s WhatsApp-based memory assistance service, web library, account surfaces, billing integrations, and ancillary features (collectively, the “Service”). By accessing or using the Service, or by otherwise submitting Content (as defined below) to Tavi, you acknowledge that you have read, understood, and agree to be bound by this Policy and our Terms of Use, and you consent to the processing described herein to the extent such consent is required under applicable law. If you do not agree, you must discontinue use of the Service and may exercise the deletion rights described in Section 8.

1. Definitions and interpretive provisions

For purposes of this Policy, the following terms have the meanings set forth below. Words importing the singular include the plural and vice versa; headings are for convenience only and shall not affect interpretation; “including” means “including without limitation.”

  • “Content” means text, voice notes and transcripts, images, screenshots, documents, files, links, contact cards, location payloads, captions, metadata, reminders, tasks, structured extractions, embeddings, and any other materials you transmit to or through the Service.
  • “Personal Data” means any information relating to an identified or identifiable natural person as defined under applicable data-protection legislation (including, where applicable, the EU/UK GDPR, analogous state privacy statutes, and other local requirements).
  • “Processing” means any operation performed on Personal Data or Content, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, restriction, erasure, or destruction.
  • “Subprocessor” means a third-party service provider engaged by Tavi to Process Personal Data or Content on Tavi’s behalf in connection with delivery of the Service.

2. Controller, scope, and applicability

Tavi acts as the party determining the purposes and means of Processing described in this Policy in relation to the Service operated at telltavi.com and associated WhatsApp business messaging channels. This Policy applies to Personal Data Processed when you message Tavi on WhatsApp, authenticate to the web library or Account surfaces, initiate exports or deletions, purchase or manage a paid plan, or otherwise interact with operational tooling necessary to provide the Service. This Policy does not govern Processing by Meta Platforms, Inc. / WhatsApp, your mobile carrier, device manufacturers, or independent third-party websites linked from Content you save, each of which is subject to its own terms and privacy notices.

Where Processing is required to perform a contract with you, to take steps at your request prior to entering into a contract, to comply with a legal obligation, or to pursue legitimate interests that are not overridden by your interests or fundamental rights and freedoms (or, where required, on the basis of consent), we rely on the corresponding lawful basis under applicable law. Nothing in this Policy constitutes legal advice to you.

3. Categories of information processed

3.1 Account and identity data

We Process identifiers associated with your WhatsApp conversation and Service account, which may include your phone number (or hashed / provider-assigned equivalents), display name where provided by the messaging channel, authentication session tokens for web Account access, subscription or entitlement status, billing customer identifiers maintained by our payment processor, and related account configuration (for example, timezone preferences used for reminders).

3.2 Content and derived representations

We Process Content you elect to send to Tavi, including without limitation: (a) message bodies and media; (b) automated speech-to-text transcripts of voice notes; (c) optical character recognition and image-understanding outputs for photos and screenshots; (d) link previews, titles, and place-name enrichment obtained from public geocoding or URL metadata helpers when you submit locations or links; (e) reminder and task schedules you create; and (f) vector embeddings, classifications, extracted entities, and other machine-generated representations created solely to index, retrieve, organize, and answer questions about Content you have stored.

3.3 Usage, diagnostics, and security telemetry

We Process limited operational logs and metrics reasonably necessary to operate, secure, bill for, and improve reliability of the Service, which may include message delivery status, error traces, latency and quota counters, approximate request volume, feature flags, and abuse / fraud signals. Where practicable, application logs are configured to avoid persisting full message bodies or raw phone numbers; residual identifiers or snippets may nonetheless appear in provider logs, incident artifacts, or support tooling.

3.4 Payment-related data

If you purchase a paid plan, payment card or alternative payment instrument data is collected and Processed by our third-party payment processor under that processor’s privacy notice. Tavi receives confirmation of subscription status, product identifiers, and transactional metadata necessary to provision entitlements and handle webhooks; Tavi does not store full payment card numbers on its own systems.

4. Sources of information

Personal Data and Content are obtained primarily from: (i) you, when you message Tavi or use Account features; (ii) Meta / WhatsApp and our messaging connectivity provider in the ordinary course of delivering inbound and outbound messages and media; (iii) authentication and hosting infrastructure; (iv) payment and email Subprocessors when you checkout or request an export; and (v) AI-inference Subprocessors that return model outputs derived from Content you submitted for Processing. We do not purchase marketing lists of end-user Content for advertising purposes.

5. Purposes and legal bases of processing

Subject to applicable law, we Process Personal Data and Content for the following purposes:

  1. Service delivery. To receive, store, index, retrieve, summarize, and return Content; to schedule and send reminders; to operate the web library and Account controls; and to provide related customer-facing functionality you request.
  2. Artificial intelligence inference. To classify intent, extract structured fields, generate embeddings, transcribe audio, interpret images, plan retrieval, and compose answers based on your stored Content, solely as required to perform the Service. See Section 7 and our Trust Centre (AI Transparency).
  3. Operations, security, and abuse prevention. To monitor availability, diagnose defects, enforce rate limits, detect fraud or misuse, protect the rights, property, and safety of Tavi, users, and the public, and comply with law enforcement or regulatory requests where legally compelled.
  4. Billing and account administration. To process subscriptions, reconcile entitlements, send transactional notices related to billing status, and maintain business records.
  5. Communications. To respond to support requests initiated through WhatsApp or Account surfaces and to provide service-related notices (including material changes to this Policy or the Terms of Use).
  6. Legal compliance and defense. To establish, exercise, or defend legal claims; to comply with applicable statutes, regulations, court orders, or lawful governmental requests.

We do not sell Personal Data. We do not Process Content for third-party advertising, behavioral advertising networks, or data-broker monetization. Aggregate or de-identified statistics that do not reasonably identify you may be used for capacity planning and product analytics.

6. Processors, subprocessors, and disclosures

We engage Subprocessors to host infrastructure and to perform discrete Processing activities. Categories of recipients include:

  • Cloud hosting and storage. Database, object storage, compute, and related managed services operated by our primary cloud infrastructure provider. Content and account data are stored with encryption in transit and at rest as provided by that provider’s standard controls.
  • Messaging channel (Meta / WhatsApp) and connectivity providers. Transmission of messages and media between your WhatsApp client and Tavi.
  • AI inference subprocessors. Unaffiliated model hosts, inference gateways, and speech-transcription processors that receive Content (and derivatives) on a transient or logged basis to generate inferences required for Service features. Specific model identifiers and AI vendor names are not publicly listed; capability categories and non-training commitments are described in Trust Centre.
  • Transactional email. Delivery of ZIP export download links and related Account emails you request.
  • Payments. Subscription checkout, invoicing, and webhook-driven entitlement updates via our payment processor.
  • Public enrichment helpers (geocoding and link-title utilities) when you submit locations or URLs, for the limited purpose of attaching place names or link metadata.

We may disclose Personal Data if we believe in good faith that disclosure is reasonably necessary to: (a) comply with law, regulation, legal process, or enforceable governmental request; (b) enforce our Terms of Use or investigate potential violations; (c) detect, prevent, or address fraud, security, or technical issues; or (d) protect against imminent harm to the rights, property, or safety of Tavi, our users, or the public as required or permitted by law. In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, Personal Data may be transferred as part of the transaction, subject to continuity of protections substantially consistent with this Policy or notice and choice as required by law.

6.1 Staff access

A limited number of authorized personnel may access operational dashboards and support tooling, subject to authentication and need-to- know restrictions, solely to operate the Service, debug delivery failures, investigate abuse, or fulfill user requests. Staff access is not used for advertising targeting.

7. Artificial intelligence and automated processing

Portions of the Service depend on automated decision-support and machine-learning inference. Content you submit may be transmitted to AI Subprocessors for classification, extraction, embedding, transcription, vision / OCR, retrieval planning, and answer generation. Such Processing is performed to deliver functionality to you and is not undertaken by Tavi for the purpose of training foundation models on your Content. Additional detail regarding capability categories and training posture appears in our Trust Centre (AI Transparency Statement), which is incorporated by reference for descriptive purposes and may be updated as our AI stack evolves. Specific model and AI-vendor identities are omitted from public disclosures.

Automated outputs may be incomplete, inaccurate, or contextually incorrect. The Service is not a substitute for professional advice (legal, medical, financial, or otherwise). You remain responsible for verifying critical information before relying on it.

8. Access, export, correction, and erasure

Depending on your jurisdiction, you may have rights to request access to, correction of, deletion of, restriction of, or portability of Personal Data, to object to certain Processing, and to withdraw consent where Processing is consent-based (without affecting the lawfulness of Processing before withdrawal). Without limiting statutory rights, the Service provides the following in-product controls:

  • Edit or delete individual notes via library / chat management flows (including instructions such as “My Memories”).
  • Request a ZIP export of notes, links, photos, and files by email from Account. Download links are time-limited (typically expiring within approximately twenty-four (24) hours). You must direct exports only to an inbox you control.
  • Delete your account and associated notes, reminders, and files from Account, subject to residual retention described in Section 9.

To exercise rights not available in-product, contact us as set forth in Section 15. We may request information reasonably necessary to verify your identity and the scope of the request. We will respond within the timeframes required by applicable law, subject to exemptions and limitations (including where fulfillment would adversely affect the rights of others, trade secrets, or legal holds).

9. Retention, backups, and residual copies

We retain Personal Data and Content for so long as your account remains active and as otherwise needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. Upon account deletion, primary Content and account records are scheduled for deletion from active systems; residual copies may persist for a limited period in encrypted backups, disaster-recovery replicas, Subprocessor logs, email inboxes (including export messages you requested), CDN or object-storage eventual-consistency windows, and similar secondary systems until those systems rotate or expire data in accordance with their retention schedules. We do not undertake to scrub every ephemeral cache instantaneously.

10. Security measures and residual risk

We implement administrative, technical, and organizational measures designed to protect Personal Data against unauthorized access, alteration, disclosure, or destruction, including transport encryption, access controls for staff tooling, and reliance on reputable cloud providers’ encryption-at-rest capabilities. No method of transmission or storage is completely secure. You acknowledge that you provide Content at your own residual risk and that you should not submit highly sensitive secrets (including bank one-time passwords, payment card numbers, government identity numbers, or credentials that would enable account takeover). Prefer abbreviated hints over complete secrets where feasible.

11. International transfers

Tavi and its Subprocessors may Process Personal Data in countries other than the country in which you reside, including the United States and other jurisdictions where cloud, messaging, payments, or AI providers operate. Where required by applicable law, we rely on appropriate transfer mechanisms (such as standard contractual clauses, provider certifications, or other lawful bases) and contractual commitments with Subprocessors. By using the Service, you understand that your information may be transferred to and Processed in such jurisdictions, which may have data-protection rules different from those of your country.

12. Children and sensitive data advisories

The Service is not directed to children under the age of sixteen (16) (or the higher age of digital consent in your jurisdiction), and we do not knowingly collect Personal Data from such children. If you believe we have collected Personal Data from a child in violation of applicable law, contact us and we will take steps to delete it. Independently of age, you should not use the Service to store special-category or highly regulated data unless you have assessed the residual risk and have a lawful basis to do so; Tavi is a practical memory assistant, not a compliance vault for regulated health, biometric, or government-identity datasets.

13. Cookies, telemetry, and similar technologies

The web portions of the Service may use cookies, local storage, or similar technologies that are strictly necessary for authentication, session continuity, security, and preference persistence. We do not operate third-party advertising pixels for cross-site behavioral advertising on the primary Service surfaces described in this Policy. Browser settings may allow you to block certain cookies; doing so may impair Account login or related features.

14. Amendments; notices

We may revise this Policy from time to time to reflect changes in the Service, Subprocessors, or legal requirements. The “Last revised” date at the top of this page will be updated accordingly. Material changes will be communicated by posting the updated Policy on this page and, where required or reasonably appropriate, by notice in WhatsApp chat or via Account surfaces. Your continued use of the Service after the effective date of a revised Policy constitutes acceptance of the revised Policy to the maximum extent permitted by law. If you do not agree, you must stop using the Service and may delete your account.

15. Contact and complaints

Questions, requests, or complaints regarding this Policy or our Processing practices may be submitted by messaging Tavi on WhatsApp and stating “privacy,” or via the Account surfaces linked from telltavi.com. If you are located in the European Economic Area, United Kingdom, or another jurisdiction that provides a right to lodge a complaint with a supervisory authority, you may do so in addition to contacting us. We encourage you to contact us first so that we may attempt to resolve your concern.

Related documents: Terms of Use · Trust Centre.